Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The Riot android client would, periodically, require re-signing in.

The certificate issues were more specifically related to Apple devices not liking that an accepted certificate had expired, and a new one had taken its place, and wouldn't even allow for the updated certificate to be "trusted" in place of the expired one. On Android I'd have to accept a new certificate to trust, and it allowed me to do so - although possibly this resulted in the requirement to re-login (and if memory serves, old messages would be unreadable).

These issues may have been of my own making, or may be fixed now, but I've been using Discord happily for a whole now.

P.S. I don't multi-account on Discord (because I didn't know you could), but I do have different names depending on the server context.



> The certificate issues were more specifically related to Apple devices not liking that an accepted certificate had expired, and a new one had taken its place, and wouldn't even allow for the updated certificate to be "trusted" in place of the expired one. On Android I'd have to accept a new certificate to trust, and it allowed me to do so - although possibly this resulted in the requirement to re-login

Huh, that doesn't sound right. You shouldn't be having to accept anything -- a renewed certificate should just work, transparently, without any interruption. You shouldn't even notice it changed.

Given that a large part of the web now uses LetsEncrypt, if this wasn't so, you would've already had problems on other websites as well.

> (and if memory serves, old messages would be unreadable).

This may have been the case if you managed to lose your keys. This is quite unlikely now since (encrypted) server-side backup of keys is supported. Additionally, if you have more than one device, one of them will likely continue to have keys and can share them with the new device once it is verified.


It may have been a quirk of the Riot client app. All I know is, whenever the cert got updated, the ipad app spat the dummy, although the message about a different certificate seemed to be more a basic ipad security warning than Riot-app-specific.

The Android Riot client was fine with the updated cert, other than the cert update possibly being the catalyst for needing to re-login.

This was three-odd years ago, not sure how much progress there's been since (including on my side in the use of certbot).

I use certbot to automate certificate updates on a couple of self-hosted sites, and it works fine for them - it really was just the ipad being repeatedly / repeatably finicky back then.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: